PJAK is a Kurdish militant group active in northwestern Iran and part of the broader Kurdish militant landscape in that region. High-confidence information available here supports its presence as an armed actor in Iran’s peripheral security environment, where it could potentially exploit weakened local control during periods of prolonged instability. The group is associated with militant activity in Iran’s northwest, but the available information does not directly establish specific cyber capabilities, ransomware activity, or a defined cyber threat profile. No corroborated details are available here on aliases beyond PJAK, sub-groups, targeting patterns, or operational tradecraft in cyberspace.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.